¡¾·ì϶¹«¸æ¡¿Î¢Èí7Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2024-07-10

 

Ò»¡¢·ì϶¸ÅÊö

2024Äê7ÔÂ10ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Î¢Èí°ä²¼ÁË7Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË142¸ö·ì϶£¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶ºÍºýŪ·ì϶µÈ ¡£

±¾´Î°²È«¸üн¨¸´ÁË4¸ö0 day·ì϶£¬ÆäÖÐÁ½¸ö±»»ý¼«ÀûÓã¬Áí±íÁ½¸öÒѾ­¹«¿ªÅû¶£º

CVE-2024-38080 £ºWindows Hyper-VÌØÈ¨ÌáÉý·ì϶

Windows Hyper-V ÖдæÔÚÕûÊýÒç³ö»ò»·±§·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8£¬ÍþвÕß¿ÉÀûÓø÷ì϶½«±¾µØÈ¨ÏÞÌáÉýΪSYSTEM ȨÏÞ£¬Ä¿Ç°¸Ã·ì϶ÒѼì²âµ½·ì϶ÀûÓà ¡£

CVE-2024-38112 £ºWindows MSHTML PlatformºýŪ·ì϶

Windows MSHTML Platform´æÔÚºýŪ·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.5£¬ÀûÓÃÄѶȽϸߣ¬ÍþвÕß¿ÉÏòÊܺ¦Õß·¢ËͶñÒâÎļþ£¬²¢ÓÕµ¼Êܺ¦ÕßÖ´ÐиÃÎļþÀ´ÀûÓø÷ì϶£¬Ä¿Ç°¸Ã·ì϶ÒѼì²âµ½·ì϶ÀûÓà ¡£

CVE-2024-35264 £º.NET ºÍ Visual StudioÔ¶³Ì´úÂëÖ´Ðзì϶

.NET ºÍ Visual StudioÖдæÔÚUse-After-Free·ì϶£¬ÍþвÕßÄܹ»Í¨¹ýÔÚ´¦ÖÃÒªÇóÖ÷Ìåʱ¹Ø¹Ø http/3 Á÷À´ÀûÓø÷ì϶£¬´Ó¶øµ¼Ö¾ºÕùǰÌᣬ³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬µ«±ØÒªÓ®µÃ¾ºÕùǰÌá ¡£Ä¿Ç°¸Ã·ì϶ÒѾ­¹«¿ªÅû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס± ¡£

CVE-2024-37985 £ºArm -רÓÐԤȡÆ÷µÄϵͳ¼ø±ðºÍ¸öÐÔ

΢Èí½¨¸´ÁË֮ǰÅû¶µÄ¿ÉÓÃÓÚÇÔÈ¡°ÂÃØÐÅÏ¢µÄFetchBench²àÐÅ·¹¥»÷£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ5.9£¬³É¹¦ÀûÓø÷ì϶µÄÍþвÕßÄܹ»´Ó·þÎñÆ÷ÉÏÔËÐеÄÌØÈ¨¹ý³Ì²é¿´¶ÑÄڴ棬µ¼ÖÂÐÅϢй¶ ¡£Ä¿Ç°¸Ã·ì϶ÒѾ­¹«¿ªÅû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס± ¡£

±¾´Î°²È«¸üÐÂÖн¨¸´µÄ5¸öÑϳÁ·ì϶Ϊ£º

CVE-2024-38023£ºMicrosoft SharePoint ServerÔ¶³Ì´úÂëÖ´Ðзì϶

Microsoft SharePoint ServerÖдæÔÚ·´ÐòÁл¯·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.2£¬ÓµÓÐÕ¾µãËùÓÐÕßȨÏ޵ľ­¹ýÉí·ÝÑéÖ¤µÄÍþвÕßÄܹ»½«ÌØÔìÎļþÉÏ´«µ½Ö¸±ê SharePoint Server£¬²¢Í¨¹ýÌØÔìAPI ÒªÇóÒÔ´¥·¢Îļþ²ÎÊýµÄ·´ÐòÁл¯£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔÚ SharePoint Server ¸ßµÍÎÄÖÐÔ¶³ÌÖ´ÐдúÂë ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ± ¡£

CVE-2024-38060£ºWindows Imaging ComponentÔ¶³Ì´úÂëÖ´Ðзì϶

Windows ͼÏñ´¦ÖÃ×é¼þÖдæÔÚ¶Ñ»º³åÇøÒç¶Âí½Å£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬¾­¹ýÉí·ÝÑéÖ¤µÄÍþвÕßÄܹ»Í¨¹ý½«¶ñÒâTIFFÎļþÉÏ´«µ½·þÎñÆ÷À´ÀûÓø÷ì϶£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ± ¡£

CVE-2024-38076£ºWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´Ðзì϶

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔÚ¶Ñ»º³åÇøÒç¶Âí½Å£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8£¬ÍþвÕßÄܹ»ÏòÉèÖÃΪԶ³Ì×ÀÃæÊÚȨ·þÎñÆ÷µÄ·þÎñÆ÷·¢ËÍÌØÔìÊý¾Ý°ü£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£ÈôÊDz»±ØÒª£¬¿É½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ×÷Ϊ»º½â´ëÊ©£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§×°Öø÷ì϶µÄ°²È«¸üУ¬¼´±ã´òËã½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס± ¡£

CVE-2024-38074£ºWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´Ðзì϶

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔÚÕûÊýÏÂÒç·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8£¬ÍþвÕßÄܹ»ÏòÉèÖÃΪԶ³Ì×ÀÃæÊÚȨ·þÎñÆ÷µÄ·þÎñÆ÷·¢ËÍÌØÔìÊý¾Ý°ü£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£ÈôÊDz»±ØÒª£¬¿É½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ×÷Ϊ»º½â´ëÊ©£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§×°Öø÷ì϶µÄ°²È«¸üУ¬¼´±ã´òËã½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס± ¡£

CVE-2024-38077£ºWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´Ðзì϶

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔÚ¶Ñ»º³åÇøÒç¶Âí½Å£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕßÄܹ»Ïνӵ½Ô¶³Ì×ÀÃæÊÚȨ·þÎñ²¢·¢ËͶñÒâÐÂÎÅ£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£ÈôÊDz»±ØÒª£¬¿É½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ×÷Ϊ»º½â´ëÊ©£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§×°Öø÷ì϶µÄ°²È«¸üУ¬¼´±ã´òËã½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס± ¡£

³ýCVE-2024-38023ºÍCVE-2024-38060±í£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ·ì϶»¹Ô̺¬£º

CVE-2024-38021£ºMicrosoft Office Ô¶³Ì´úÂëÖ´Ðзì϶

ÍþвÕßÄܹ»Ôì×÷Ò»¸öÈÆ¹ýÊܱ£»¤ÊÓͼºÍ̸µÄ¶ñÒâÁ´½ÓÀ´ÀûÓø÷ì϶£¬´Ó¶øÔÚÓû§½»»¥µÄÇé¿öϵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£

CVE-2024-38024/ CVE-2024-38094£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft SharePoint ServerÖдæÔÚ¶à¸ö·´ÐòÁл¯·ì϶£¬ÓµÓÐÕ¾µãËùÓÐÕßȨÏ޵ľ­¹ýÉí·ÝÑéÖ¤µÄÍþвÕßÄܹ»ÀûÓø÷ì϶עÈëËÁÒâ´úÂë²¢ÔÚ SharePoint Server ¸ßµÍÎÄÖÐÖ´ÐÐ ¡£

CVE-2024-38052£ºKernel Streaming WOW Thunk Service DriverÌØÈ¨ÌáÉý·ì϶

Kernel Streaming WOW Thunk Service DriverÖдæÔÚÊäÈëÑéÖ¤²»µ±·ì϶£¬³É¹¦ÀûÓø÷ì϶¿É»ñµÃSYSTEM ȨÏÞ ¡£

CVE-2024-38054£ºKernel Streaming WOW Thunk Service DriverÌØÈ¨ÌáÉý·ì϶

Kernel Streaming WOW Thunk Service DriverÖдæÔÚ¶Ñ»º³åÇøÒç¶Âí½Å£¬³É¹¦ÀûÓø÷ì϶¿É»ñµÃSYSTEM ȨÏÞ ¡£

CVE-2024-38059£ºWin32k ÌØÈ¨ÌáÉý·ì϶

Win32kÖдæÔÚUse-After-Free·ì϶£¬³É¹¦ÀûÓø÷ì϶¿É»ñµÃSYSTEM ȨÏÞ ¡£

CVE-2024-38066£ºWindows Win32k ÌØÈ¨ÌáÉý·ì϶

Windows Win32kÖдæÔÚUse-After-Free·ì϶£¬³É¹¦ÀûÓø÷ì϶¿É»ñµÃSYSTEM ȨÏÞ ¡£

CVE-2024-38079£ºWindows Graphics ComponentÌØÈ¨ÌáÉý·ì϶

Windows ͼÐÎ×é¼þÖдæÔÚ¶Ñ»º³åÇøÒç¶Âí½Å£¬±¾µØÍþвÕßÄܹ»ÔËÐпÉÀûÓø÷ì϶µÄÌØÔìÀûÓ÷¨Ê½£¬³É¹¦ÀûÓÃÄܹ»»ñµÃSYSTEM ȨÏÞ ¡£

CVE-2024-38085£ºWindows Graphics ComponentÌØÈ¨ÌáÉý·ì϶

Windows ͼÐÎ×é¼þÖдæÔÚUse-After-Free·ì϶£¬³É¹¦ÀûÓø÷ì϶¿É»ñµÃSYSTEM ȨÏÞ ¡£

CVE-2024-38099£ºWindows Remote Desktop Licensing Service»Ø¾ø·þÎñ·ì϶

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔÚÉí·ÝÑéÖ¤²»µ±·ì϶£¬³É¹¦ÀûÓø÷ì϶±ØÒªÍþвÕßÕ¼Óи߼¶ÄæÏò¹¤³Ì¼¼ÊõÀ´¼ø±ð²¢»ñµÃ¶ÔÌØ¶¨Ô¶³Ì¹ý³ÌŲÓà (RPC) ¶ËµãµÄδ¾­ÊÚȨµÄ½Ó¼û£¬³É¹¦ÀûÓÿÉÄܵ¼Ö»ؾø·þÎñ ¡£

CVE-2024-38100£ºWindows File ExplorerÌØÈ¨ÌáÉý·ì϶

Windows Îļþ×ÊÔ´ÖÎÀíÆ÷´æÔÚ½Ó¼û½ÚÔì²»µ±·ì϶£¬³É¹¦ÀûÓô˷ì϶µÄÍþвÕßÄܹ»»ñµÃÖÎÀíԱȨÏÞ ¡£

΢Èí7Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑϳÁÐÔ

CVE-2024-38023

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-38060

Windows Imaging Component Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-38076

Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-38074

Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-38077

Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-30105

.NET Core ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38081

.NET¡¢.NET Framework ºÍ Visual Studio ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-35264

.NET ºÍ Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38095

.NET ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38092

Azure CycleCloud ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-35266

Azure DevOps Server ºýŪ·ì϶

¸ßΣ

CVE-2024-35267

Azure DevOps Server ºýŪ·ì϶

¸ßΣ

CVE-2024-38086

Azure Kinect SDK Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-35261

Azure Network Watcher VM Extension ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-37985

Arm£ºCVE-2024-37985 רÓÐԤȡÆ÷µÄϵͳ¼ø±ðºÍ¸öÐÔ

¸ßΣ

CVE-2024-38027

Windows Line Printer Daemon Service »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38089

Microsoft Defender for IoT ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-30061

Microsoft Dynamics 365 (On-Premises) ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-38079

Windows Graphics Component ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38051

Windows Graphics Component Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38021

Microsoft Office Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38024

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-32987

Microsoft SharePoint Server ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-38094

Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38057

Kernel Streaming WOW Thunk Service Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38054

Kernel Streaming WOW Thunk Service Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38052

Kernel Streaming WOW Thunk Service Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38055

Microsoft Windows Codecs Library ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-38056

Microsoft Windows Codecs Library ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-38091

Microsoft WS-Discovery »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38048

Windows Network Driver Interface Specification   (NDIS) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-3596

CERT/CC£ºCVE-2024-3596 RADIUS ºÍ̸ºýŪ·ì϶

¸ßΣ

CVE-2024-38061

DCOM Remote Cross-Session Activation ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38080

Windows Hyper-V ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-28928

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38088

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-20701

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21317

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21331

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21308

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21333

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-35256

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21303

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21335

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-35271

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-35272

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21332

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38087

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21425

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21449

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37324

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37330

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37326

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37329

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37328

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37327

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37334

Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37321

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37320

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37319

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37322

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37333

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37336

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37323

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37331

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21398

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21373

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37318

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21428

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21415

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37332

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21414

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38058

BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-38100

Windows File Explorer ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21417

Windows Text Services Framework ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-30098

Windows Cryptographic Services °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-38044

DHCP Server Service Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38049

Windows Distributed Transaction Coordinator Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38069

Windows Enroll Engine °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-38104

Windows Fax Service Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38034

Windows Filtering Platform ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38022

Windows Image Acquisition ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38105

Windows Layer-2 Bridge Network Driver »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38053

Windows Layer-2 Bridge Network Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38102

Windows Layer-2 Bridge Network Driver »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38101

Windows Layer-2 Bridge Network Driver »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-35270

Windows iSCSI Service »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38041

Windows Kernel ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-38062

Windows Kernel-Mode Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38070

Windows LockDown Policy (WLDP) °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-38017

Microsoft Message Queuing ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-38112

Windows MSHTML Platform ºýŪ·ì϶

¸ßΣ

CVE-2024-30013

Windows MultiPoint Services Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-30081

Windows NTLM ºýŪ·ì϶

¸ßΣ

CVE-2024-38068

Windows Online Certificate Status Protocol (OCSP)   Server »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38067

Windows Online Certificate Status Protocol (OCSP)   Server »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38031

Windows Online Certificate Status Protocol (OCSP)   Server »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38028

Microsoft Windows Performance Data Helper Library   Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38019

Microsoft Windows Performance Data Helper Library   Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38025

Microsoft Windows Performance Data Helper Library   Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38043

PowerShell ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38047

PowerShell ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38033

PowerShell ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-30071

Windows Remote Access Connection Manager ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-30079

Windows Remote Access Connection Manager ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38015

Windows Remote Desktop Gateway (RD Gateway) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38071

Windows Remote Desktop Licensing Service »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38073

Windows Remote Desktop Licensing Service »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38072

Windows Remote Desktop Licensing Service »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38099

Windows Remote Desktop Licensing Service »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38065

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37986

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37981

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37987

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-28899

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-26184

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-38011

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37984

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37988

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37977

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37978

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37974

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-38010

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37989

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37970

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37975

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37972

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37973

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37971

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-37969

Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-38013

Microsoft Windows Server Backup ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38064

Windows TCP/IP ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-38030

Windows Themes ºýŪ·ì϶

¸ßΣ

CVE-2024-38085

Windows Graphics Component ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38066

Windows Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38059

Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38050

Windows Workstation Service ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38032

Microsoft Xbox Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38078

Xbox Wireless Adapter Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-39684

Github£ºCVE-2024-39684 TenCent   RapidJSON ÌØÈ¨ÌáÉý·ì϶

ÖÐΣ

CVE-2024-38517

Github£ºCVE-2024-38517 TenCent   RapidJSON ÌØÈ¨ÌáÉý·ì϶

ÖÐΣ

CVE-2024-38020

Microsoft Outlook ºýŪ·ì϶

ÖÐΣ

 


¶þ¡¢Ó°ÏìÁìÓò

ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º

SQL Server

Windows CoreMessaging

Windows Secure Boot

Windows MultiPoint Services

Microsoft Dynamics

Windows Remote Access Connection Manager

Windows NTLM

Windows Cryptographic Services

.NET and Visual Studio

Microsoft Office SharePoint

Azure Network Watcher

Azure DevOps

Windows iSCSI

Windows Server Backup

Windows Remote Desktop

Windows Message Queuing

Windows Performance Monitor

Microsoft Office Outlook

Microsoft Office

Windows Image Acquisition

Line Printer Daemon Service (LPD)

Windows Themes

Windows Online Certificate Status Protocol (OCSP)

XBox Crypto Graphic Services

Windows PowerShell

Windows Filtering

Windows Kernel

Windows DHCP Server

NDIS

Windows Distributed Transaction Coordinator

Windows Workstation Service

Microsoft Graphics Component

Microsoft Streaming Service

Windows Internet Connection Sharing (ICS)

Microsoft Windows Codecs Library

Windows BitLocker

Windows Win32K - ICOMP

Role: Active Directory Certificate Services; Active Directory Domain Services

Windows Kernel-Mode Drivers

Windows TCP/IP

Windows Win32K - GRFX

Windows Enroll Engine

Windows LockDown Policy (WLDP)

Windows Remote Desktop Licensing Service

Active Directory Federation Services

Role: Windows Hyper-V

Windows Win32 Kernel Subsystem

Azure Kinect SDK

Microsoft Defender for IoT

Microsoft WS-Discovery

Azure CycleCloud

Windows COM Session

Windows Fax and Scan Service

Windows MSHTML Platform

 


Èý¡¢°²È«´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´ ¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öà ¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüР¡£

4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üР¡£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öà ¡£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüР¡£

2024Äê7Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó ¡£

image.png

Àý1£ºÎ¢Èí·ì϶ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó ¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öà ¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú ¡£

3.2 һʱ´ëÊ©

ÔÝÎÞ ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ ¡£

l  ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È ¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä ¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul

https://blog.qualys.com/vulnerabilities-threat-research/2024/07/09/microsoft-patch-tuesday-july-2024-security-update-review

https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2024-patch-tuesday-fixes-142-flaws-4-zero-days/

 


ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-07-10

³õ´Î°ä²¼

 


Îå¡¢¸½Â¼

5.1 GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò» ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË ¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊÐ ¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦ ¡£

5.2 ¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½ ¡£

¹Ø×¢ÎÒÃÇ£º

image.png